GSLC Exam Questions
575 real GSLC exam questions with expert-verified answers and explanations. Page 3 of 12.
- Question #103Security Architecture & Engineering
A Security administrator wants to configure policies that dictate what types of network traffic are allowed in the network. Which types of signature should he use to configure such...
IDS signaturesconnection signaturestraffic policynetwork security - Question #104Security Architecture & Engineering
Which of the following tools is used to hide secret data in text files and is based on the concept that spaces and tabs are generally not visible in text viewers and therefore a me...
steganographySnow.exewhitespace encodingdata hiding - Question #105Security Architecture & Engineering
Which of the following uses public key cryptography to encrypt the contents of files?
EFSpublic key cryptographyfile encryptionWindows - Question #106Security Architecture & Engineering
You are trying to select a particular wireless encryption algorithm. You are concerned that it implements as much of the wireless 802.11i standard as possible. Which encryption alg...
WPA2802.11iwireless encryptionwireless security - Question #107Security Operations & Incident Response Leadership
Which of the following would allow you to automatically close connections or restart a server or service when a DoS attack is detected?
active IDSautomated responseDoS detectionintrusion prevention - Question #108Security Architecture & Engineering
Which of the following files must be configured to enable hostname lookups to use the Domain Name Service (DNS)?
DNS configurationnsswitch.confhostname resolutionLinux - Question #109Risk Management & Compliance
You work as a project manager for BlueWell Inc. You are working with your team members on the risk responses in the project. Which risk response will likely cause a project to use...
risk sharingrisk responseprocurementproject management - Question #110Security Operations & Incident Response Leadership
A user in your department complains about a slow Internet connection. You monitor the external interface of your company's border router and notice an excessive number of half-open...
TCP SYN floodhalf-open connectionsDoS attacknetwork forensics - Question #111Security Architecture & Engineering
You have configured a virtualized Internet browser on your Windows XP professional computer. Using the virtualized Internet browser, you can protect your operating system from whic...
browser virtualizationsandboxingmalware isolationendpoint security - Question #112Security Program Management & Governance
You are the program manager of the JNH Program. Tom, a project manager in your program, has just completed his project and is ready to officially close his project. You agree that...
program managementproject closuregovernancestakeholder roles - Question #113Security Operations & Incident Response Leadership
You work as a Network Administrator for Marioxnet Inc. You have the responsibility of handling two routers with BGP protocol for the enterprise's network. One of the two routers ge...
DoS attackBGP floodingnetwork availabilityattack identification - Question #114Security Architecture & Engineering
Which of the following can be used to mitigate the evil twin phishing attack?
evil twin attackIPSec VPNwireless phishingnetwork countermeasures - Question #115Security Program Management & Governance
Nancy is the project manager for YYF project. She is receiving bids and proposals from different vendors. She will apply previously defined selection criteria to select one or more...
procurement managementvendor selectionproposal evaluationConduct Procurements - Question #116Security Architecture & Engineering
US Garments wants all encrypted data communication between corporate office and remote location. They want to achieve following results: - Authentication of users - Anti-replay - A...
IPSecAuthentication Headeranti-replaypacket integrity - Question #117Security Program Management & Governance
Which of the following are examples of administrative controls that involve all levels of employees within an organization and determine which users have access to what resources a...
administrative controlsaccess controlsecurity awareness trainingdisaster recovery - Question #118Risk Management & Compliance
Eric is the project manager of the NQQ Project and has hired the ZAS Corporation to complete part of the project work for Eric's organization. Due to a change request the ZAS Corpo...
contract terminationprocurementlegal liabilityvendor management - Question #119Security Architecture & Engineering
Which of the following features is used to generate spam on the Internet by spammers and worms?
SMTP relayspamemail securityopen relay abuse - Question #120Security Operations & Incident Response Leadership
You work as a Consumer Support Technician for ABC Inc. The company provides troubleshooting support to users. You are troubleshooting a computer of a user who is working on Windows...
patch managementautomatic updatesvulnerability remediationWindows Security Center - Question #121Security Architecture & Engineering
Which of the following is a fake target that deters hackers from locating your real network?
honeypotdeception technologynetwork securityintrusion detection - Question #122Security Operations & Incident Response Leadership
Brutus is a password cracking tool that can be used to crack the following authentications: - HTTP (Basic Authentication) - HTTP (HTML Form/CGI) - POP3 (Post Office Protocol v3) -...
password crackingdictionary attackbrute forcehybrid attack - Question #123Security Architecture & Engineering
Which of the following statements about a host-based intrusion prevention system (HIPS) are true? Each correct answer represents a complete solution. Choose two.
HIPShost-based IPSintrusion preventionencrypted traffic - Question #124Security Awareness & Training
John works as a professional Ethical Hacker. He has been assigned the project of testing the The e-mail that John has received is an example of __________.
social engineeringchain lettersemail threatsphishing - Question #125Security Architecture & Engineering
An Active Attack is a type of steganography attack in which the attacker changes the carrier during the communication process. Which of the following techniques is used for smoothi...
steganographyactive attackimage manipulationblur technique - Question #126Security Architecture & Engineering
Which of the following statements about Public Key Infrastructure (PKI) are true? Each correct answer represents a complete solution. Choose two.
PKIasymmetric encryptiondigital signatureskey pairs - Question #127Security Program Management & Governance
Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration managem...
change managementconfiguration managementconfiguration identificationscope changes - Question #128Security Program Management & Governance
Donna is the project manager for her organization. She is preparing a plan to manage changes to the project should changes be requested. Her change management plan defines the proc...
change controlPMISproject managementchange management plan - Question #129Security Operations & Incident Response Leadership
Mark works as a Network Administrator for Technet Inc. The company has a Windows 2003 domainbased network. The network has a file server that uses a RAID-5 volume. The RAID-5 volum...
RAID-5fault tolerancedisk managementdata recovery - Question #130Security Architecture & Engineering
Which type of attack is the unauthorized access of information from a wireless device through a Bluetooth connection, often between phones, desktops, laptops, and PDAs?
bluesnarfingBluetooth securitywireless attacksunauthorized access - Question #131Security Operations & Incident Response Leadership
The Incident handling process implemented in an enterprise is responsible to deal with all the incidents regarding the enterprise. Which of the following procedures will be involve...
incident handlingincident responsepreparation phaseincident response kit - Question #132Security Awareness & Training
Which of the following types of attacks cannot be prevented by technical measures only?
social engineeringhuman factortechnical controlsattack prevention - Question #133Security Architecture & Engineering
Maria works as a professional Ethical Hacker. She recently has been assigned a project to test about the infrastructure of its network: - Network diagrams of the we-are-secure infr...
white box testingpenetration testingsecurity testing methodologynetwork assessment - Question #134Security Architecture & Engineering
Adam works as a Professional Penetration Tester for Umbrella Inc. A project has been assigned to him to carry out a Black Box penetration testing as a regular evaluation of the sys...
black box testingpenetration testingethical hackingsecurity assessment - Question #135Security Architecture & Engineering
Which model is a software development process combining elements of both design and prototyping-in-stages, in an effort to combine advantages of top-down and bottom-up concepts?
spiral modelSDLCsoftware developmentprototyping - Question #136Security Architecture & Engineering
Which of the following is used to translate domain names into the numerical (binary) identifiers associated with networking equipment for the purpose of locating and addressing the...
DNSdomain name resolutionnetwork protocolIP addressing - Question #137Security Architecture & Engineering
You are the Network Administrator for a large corporate network. You want to monitor all network traffic on your local network for suspicious activities and receive a notification...
NIDSnetwork monitoringintrusion detectiontraffic analysis - Question #138Security Architecture & Engineering
Which of the following refers to the process of verifying the identity of a person, network host, or system process?
authenticationidentity verificationaccess controlsecurity fundamentals - Question #139Security Architecture & Engineering
Which of the following are the countermeasures against a man-in-the-middle attack? Each correct answer represents a complete solution. Choose all that apply.
man-in-the-middleMITM countermeasuresPKI authenticationoff-channel verification - Question #140Security Operations & Incident Response Leadership
You work as an Exchange Administrator for McRobert Inc. You are configuring a new Exchange 2000 Server computer and two storage groups, group A and group B, on your network. You ha...
Exchange Serverstorage groupsdisk configurationhigh availability - Question #141Security Architecture & Engineering
Which of the following security policies will you implement to keep safe your data when you connect your Laptop to the office network over IEEE 802.11 WLANs? Each correct answer re...
WLAN securitypersonal firewallIPSec VPNwireless policy - Question #142Security Operations & Incident Response Leadership
You work as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. You are working as a root user on the Linux operating system. Your company is...
IP spoofingnetwork attack detectionLinux security toolsintrusion detection - Question #143Security Program Management & Governance
What course of action can be taken by a party if the current negotiations fail and an agreement cannot be reached?
BATNAnegotiationconflict resolutionstakeholder management - Question #144Security Program Management & Governance
You are the project manager of the GYG Project. A new scope change is being considered for your project. You are concerned, however, that the scope change may add costs, risks, and...
integrated change controlscope changeproject managementchange control board - Question #145Security Architecture & Engineering
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Active Directory-based single domain single forest network. The functional level of the forest i...
asymmetric encryptionpublic key cryptographymessage confidentialityPKI - Question #146Security Operations & Incident Response Leadership
John, a malicious hacker, forces a router to stop forwarding packets by flooding it with many open connections simultaneously so that all hosts behind it are effectively disabled....
DoS attackrouter floodingnetwork attack typesavailability attack - Question #147Security Program Management & Governance
Donna, a stakeholder in your project to create new software, has approached you about adding some features to the software package. You instruct that Donna must document the change...
change request documentationaudit trailchange managementstakeholder management - Question #148Risk Management & Compliance
Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?
AROrisk quantificationthreat frequencyquantitative risk analysis - Question #149Security Architecture & Engineering
The MBR of a hard disk is a collection of boot records that contain disk information such as disk architecture, cluster size, and so on. The main work of the MBR is to locate and r...
MBR infectionboot sector virusmultipartite virusmalware types - Question #150Security Awareness & Training
John works as an IT Technician for PassGuide Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company p...
social engineeringcredential phishinguser security awarenessattack recognition - Question #151Security Program Management & Governance
Tim is working as a project manager for the TCH project. The project is in the final stages and the closing processes are being performed. He has prepared the lessons learned docum...
lessons learnedproject closureorganizational process assetsproject documentation - Question #152Risk Management & Compliance
Which of the following Acts enacted in United States allows the FBI to issue National Security Letters (NSLs) to Internet service providers (ISPs) ordering them to disclose records...
ECPANational Security Lettersprivacy lawlegal compliance